World Watch/Panama/Cybersecurity

Cybersecurity · Panama

Cybersecurity regulation in Panama (2026)

Sectoral rulesLaw 478 of 2025 (cybercrime amendments to Penal Code), Law 81 of 2019 (data protection / breach notification), National Cybersecurity Strategy 2021–2024, AIG / CSIRT-PanamaCountry index 70 · B

Panama shaded by its cybersecurity status

Panama's cybersecurity regime is sectoral rather than comprehensive: criminal liability for cyber-offences is governed by the Penal Code as most recently amended by Law 478 of August 2025, while breach-notification duties derive from the 2019 Personal Data Protection Law (Law 81). The National Authority for Government Innovation (AIG) operates CSIRT-Panama for incident response and coordinated the 2021–2024 National Cybersecurity Strategy; no single omnibus statute equivalent to NIS2 is in force.

Key points

Law 478 (2025) – Cybercrime

Enacted 4 August 2025, Law 478 amends the Penal Code, Code of Criminal Procedure, and Law 11 of 2015 to criminalise digital extortion, sextortion, identity theft, and attacks on critical infrastructure (hospital, banking, energy systems); penalties run 5–10 years imprisonment with a 50 % uplift where ICT tools are used.

Breach notification – Law 81 (2019)

Law 81 of 26 March 2019 (Personal Data Protection Law), supplemented by Executive Decree 285 of 2021, requires organisations to notify the National Authority for Transparency and Access to Information (ANTAI) of personal data breaches within 72 hours of becoming aware of the incident.

National Cybersecurity Strategy 2021–2024

Approved by AIG Resolution No. 17 and published in Official Digital Gazette No. 29434-A, the strategy establishes four pillars: protecting privacy and rights, deterring cybercrime, securing critical national infrastructure, and building a national cybersecurity culture.

AIG / CSIRT-Panama

The National Authority for Government Innovation (AIG) hosts CSIRT-Panama, the national computer-security incident-response team. In April 2026 the government activated its first Cyber Monitoring Center following a series of public-sector hacking incidents, expanding real-time threat-detection capacity.

Sectoral obligations – Banking

The Superintendency of Banks (SBP) and AIG signed an inter-institutional cybersecurity agreement to share threat intelligence, improve incident reporting, and strengthen digital-security obligations specifically for the financial sector, operating alongside the general data-protection requirements.

Budapest Convention participation

Panama participates in the Council of Europe Budapest Convention's 24/7 Network for international cooperation on electronic evidence and cybercrime, a mechanism explicitly reinforced and cited in Law 478 of 2025.

Panama - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →